SMB Firewall Buyer's Guide 2026: How to Choose the Right Firewall
A firewall buyer's guide for SMBs in 2026 has to answer three questions: how much speed does the appliance keep while it inspects encrypted traffic, which security services are included in the license, and who will operate it? Choosing the right firewall rests on the Threat Protection figure measured with every protection enabled and on your organization's real traffic, not on the largest number printed on the datasheet.
Why Is Choosing a Firewall Different in 2026?
Choosing a firewall in 2026 differs from five years ago because the vast majority of web traffic is encrypted, ransomware hits small businesses more often than large enterprises, and classic SSL VPN is giving way to IPsec and zero-trust access. These three shifts move the selection criterion from raw bandwidth to encrypted-traffic inspection and identity-based access.
The first shift is encrypted traffic. A firewall cannot see the file, the command or the data leak inside an HTTPS connection without opening it. SSL/TLS inspection is the most resource-hungry operation an appliance performs, which is why the impressive Firewall throughput figure on the datasheet shrinks to a much smaller number once inspection is switched on. An NGFW that does not inspect encrypted traffic behaves, in practice, like an advanced router.
The second shift is the threat landscape. Verizon's 2025 Data Breach Investigations Report (DBIR) found ransomware present in 44 percent of the breaches it analyzed; among small and medium-sized businesses the share reached 88 percent, compared with 39 percent at large organizations. Attackers know that companies with small defense budgets are easier targets, and the firewall remains the first and most fundamental layer of defense in that picture.
The third shift is the remote-access model. Fortinet has been phasing SSL VPN out across the FortiOS 7.6 series and positions IPsec and ZTNA as the recommended path; verify in the official release notes what was removed on which model and version before you plan. An appliance bought today should connect remote staff through an IPsec client or identity-based application access rather than an SSL VPN portal.
Compliance points the same way. The Turkish Data Protection Authority's Personal Data Security Guide (Technical and Administrative Measures) names the firewall and the network gateway as the first line of defense against unauthorized access from the internet, and lists patch management and the removal of unused services among the priority measures. For any business processing personal data in Turkey, a properly configured firewall is therefore part of a legal obligation as well as a technical one; always verify the current legislation and the official guide. If you want a refresher on what a firewall does, start with our guide on what a FortiGate firewall is.
Needs Analysis: Which Questions Must You Answer First?
A firewall needs analysis starts with seven questions: how many users and devices are there, what is the internet line speed today and in three years, how many branches and remote workers will connect, which servers are reachable from outside, which cloud services are in use, which regulations apply, and who will manage the appliance? The answers determine the model class and the license bundle.
The most common mistake we see in the field is starting and ending the analysis with a headcount. Fortinet datasheets do not publish user counts, because a 30-person accounting office and a 30-person video production studio do not generate the same traffic. When you count, add IP phones, printers, cameras, cash registers and POS terminals and the phones on the guest Wi-Fi to the computers; these devices inflate concurrent sessions more than anything else.
| Question | Why it matters | Effect on the choice |
|---|---|---|
| How many users and devices? | Determines concurrent sessions and new sessions per second | Model class, session table capacity |
| Line speed today and in three years? | The appliance must fill the line with inspection enabled | Threat Protection and SSL Inspection threshold |
| How many branches and remote workers? | Number of tunnels and encryption load | IPsec VPN throughput, ZTNA need, SD-WAN |
| Servers reachable from outside? | Published services are attack surface | IPS, DMZ segment, WAF if required |
| Which cloud services? | SaaS traffic shapes egress bandwidth and DNS security | Application control, DNS filtering, SD-WAN |
| Which regulations apply? | Log retention duties under KVKK and Law 5651 | Logging, FortiAnalyzer or external log server |
| Who will manage it? | An unconfigured NGFW protects nothing | In-house team, managed service, support tier |
An organization that has filled in this table now holds a profile. A single-office business with 25 users, a 200 Mbps line, two remote workers and one accounting server does not buy from the same model class as a manufacturer with three branches, 120 users and an ERP server at headquarters. Writing the profile down ensures that the conversation at quotation time revolves around your criteria rather than the vendor's.
Which Datasheet Figure Actually Matters?
On a firewall datasheet the decisive value for an SMB is not Firewall throughput but Threat Protection throughput: the speed measured with IPS, antivirus and application control enabled at the same time. Where encrypted traffic will be inspected, the second critical value is SSL Inspection throughput; where branches will be linked by tunnels, it is IPsec VPN throughput.
The main datasheet values mean the following:
- Firewall throughput: Raw forwarding speed with no security profile enabled, measured at different packet sizes (1518 / 512 / 64 byte UDP). It is the largest number in marketing material and the least meaningful for the decision.
- IPS throughput: Speed with only the intrusion prevention engine enabled.
- Threat Protection throughput: Speed with IPS, antivirus and application control enabled together. This is the value closest to an SMB's real operating condition.
- SSL Inspection throughput: The speed the appliance sustains while decrypting and inspecting encrypted traffic. If deep inspection is enabled for every user, this is the practical ceiling.
- IPsec VPN throughput: Encrypted traffic capacity across site-to-site or remote-access tunnels.
- Concurrent sessions and new sessions per second: The two capacity values that create bottlenecks in device-heavy environments and guest networks.
The rule of thumb we apply in our projects: the Threat Protection figure should be at least one and a half times the speed you expect your internet line to have in three years, and if deep SSL inspection will be enabled for all users, the SSL Inspection figure should not fall below today's line speed. The table below places four entry-level FortiGate models side by side using the values from Fortinet's official datasheets.
| Model | Firewall throughput | Threat Protection | SSL Inspection | IPsec VPN | Typical placement |
|---|---|---|---|---|---|
| FortiGate 40F | 5 Gbps | 600 Mbps | 310 Mbps | 4.4 Gbps | Micro office, checkout/POS site, small single-line branch |
| FortiGate 60F | 10 Gbps | 700 Mbps | 630 Mbps | 6.5 Gbps | Classic branch; the most common entry model |
| FortiGate 70G | 10 Gbps | 1.3 Gbps | 1.4 Gbps | 7.1 Gbps | Branch or small head office running SSL inspection |
| FortiGate 90G | 28 Gbps | 2.2 Gbps | 2.6 Gbps | 25 Gbps | Hub of a multi-branch network, heavy tunnel traffic |
The values are taken from Fortinet datasheets; for the current product matrix see the Fortinet Product Matrix. The table tells a clear story: the 60F and 70G share the same Firewall throughput, yet with SSL inspection enabled the 70G retains more than twice the capacity. We examine the differences between these models, including port layout, ASIC generation and Wi-Fi/PoE variants, in our FortiGate 40F, 60F, 70G and 90G comparison; the full series is listed on our FortiGate solutions page.
How Do You Choose Security Features and the License Bundle?
Choosing the firewall license bundle is as decisive as choosing the hardware: the same FortiGate model delivers a different level of protection with the FortiGuard ATP, UTP or Enterprise bundle. The bundles are nested: ATP provides threat protection, UTP adds web and DNS security on top, and Enterprise adds data loss prevention and IoT visibility. For most SMBs whose users browse the internet, UTP is the starting point.
An unlicensed NGFW performs only stateful packet filtering and VPN; without signature updates it does not recognize new threats. When you compare quotations, therefore, read appliance, license and support as a single line item. The general orientation of the bundles is as follows; because the vendor updates their contents, verify the current ordering guide at the time of purchase:
- ATP (Advanced Threat Protection): Covers IPS, application control and anti-malware that combines antivirus with cloud-based sandbox analysis. A threat-focused, narrower bundle for environments where content filtering happens in another layer.
- UTP (Unified Threat Protection): Adds URL (web) filtering, DNS filtering, video filtering and botnet / command-and-control blocking to the ATP scope. A balanced bundle for the classic office where users browse the internet.
- Enterprise Protection: The broadest bundle, adding services such as data loss prevention (DLP), attack surface monitoring and risk scoring, AI-based inline malware prevention and IoT device detection to the UTP scope.
The second decision that accompanies the license is the support tier. FortiCare Premium provides round-the-clock technical support and hardware replacement; the Elite tier adds faster response targets and additional services. The term (1, 3 or 5 years) directly affects total cost and the renewal workload: a longer term lowers the unit cost but leaves the risk of technology change with you. We describe the bundles in detail in our article on the differences between FortiGuard UTP, ATP and Enterprise.
Is a Firewall Enough on Its Own? Switches, Wi-Fi and Remote Access
A firewall is not enough on its own; a threat that starts inside the network (an infected laptop, a phone on the guest Wi-Fi, a misconfigured VPN client) never passes the firewall at the internet edge. In 2026 an SMB architecture should be planned as an integrated design in which the firewall, managed switches, enterprise Wi-Fi and identity-based remote access are operated from a single console.
Segmentation is the backbone of that architecture. User computers, servers, IP cameras and IoT devices, the guest network and management interfaces live in separate VLANs, and traffic between segments passes through firewall policy. When ransomware tries to spread from a user's computer to the server segment, it runs into policy and IPS. This requires the access-layer switch to talk to the firewall; the FortiLink protocol turns a FortiSwitch into a port extension managed from the FortiGate interface. We gathered the selection criteria in our FortiSwitch and FortiLink selection guide.
The same principle applies to wireless: when enterprise Wi-Fi access points are managed through the firewall, guest, staff and IoT SSIDs land directly in the relevant VLAN and are governed by the same policy set. For remote access, the goal is to grant users access only to the applications they are authorized for, after verifying identity and device posture, instead of a tunnel that opens the whole network; we compare that approach with VPN in our article on what ZTNA is.
Finally, continuity: if the internet connection is business-critical, plan line redundancy with two WAN links and SD-WAN; if an appliance failure is unacceptable, plan a high-availability (HA) cluster with a second unit. HA means twice the hardware budget for the model you choose, which is why a single-office SMB usually adds line redundancy first and appliance redundancy later.
How Do You Calculate Total Cost of Ownership?
The total cost of ownership of a firewall is more than the appliance itself; over a three- to five-year period it combines the license subscription, the support tier, installation and migration, the labor spent on day-to-day operation and the indirect cost of a possible outage. In our field experience, subscription and operations frequently outweigh the hardware's share by the end of the period.
To build the budget correctly, list the items separately:
- Hardware: Model, Wi-Fi/PoE variant, a second unit for HA, FortiSwitch and FortiAP where needed.
- Subscription: FortiGuard bundle (UTP/ATP/Enterprise) and term; renewal calendar.
- Support: FortiCare tier and hardware replacement time.
- Installation and migration: Moving existing rules, rule cleanup, testing and the maintenance window.
- Operations: Hours spent on patches and firmware updates, rule changes, log review and incident response.
- Outage risk: The cost of the time the business stands still due to misconfiguration or failure.
We explain the factors that drive the price along the model, bundle and term axes in our article on what determines FortiGate pricing, and our 2026 cybersecurity budget guide shows how to rank the firewall against the other security line items. The operations item is what really separates an in-house team from a managed service:
| Criterion | Managed by your own team | Managed firewall service |
|---|---|---|
| Firmware and signature updates | Depends on the team's calendar; often postponed | Performed by the provider in a planned maintenance window |
| Rule changes | On request; documentation often incomplete | Change log and periodic rule audit |
| Log monitoring and alerts | Usually reviewed after an incident | Continuous monitoring, threshold-based alerts |
| Expertise | Risk of dependence on one person | Team knowledge, experience from many deployments |
| Cost structure | Fixed staff cost plus training | Predictable recurring service fee |
| Best fit | Organizations with an experienced in-house IT team | SMBs with a small or no IT team |
You can weigh which model fits you, together with a scope and responsibility matrix, in our article on what a managed firewall service is.
Step-by-Step Selection Checklist
The firewall selection checklist has ten steps: inventory, line capacity, Threat Protection threshold, SSL inspection decision, license bundle, remote-access model, segmentation, logging and compliance, management model and lifecycle plan. An organization that answers every step in writing compares only commercial terms at quotation time, not models.
- Build the inventory: Write down users, devices, servers, branches and remote workers; do not forget IoT and guest devices.
- Project line capacity three years ahead: Note today's speed and the planned upgrades.
- Set the Threat Protection threshold: Aim for at least one and a half times the future line speed.
- Decide on SSL inspection: All users, or only risky categories? The decision sets the SSL Inspection threshold.
- Choose the license bundle: UTP, ATP or Enterprise; think about the term together with your renewal process.
- Clarify the remote-access model: IPsec client, ZTNA, or both together?
- Design segmentation: VLAN plan, guest and IoT separation, switch management via FortiLink.
- Plan logging and compliance: Where and how long logs are kept under KVKK and Law 5651; verify the current legislation.
- Choose the management model: In-house team or managed service; set the support tier accordingly.
- Write the lifecycle plan: License end date, firmware policy and the person responsible for tracking the vendor's end-of-life notices.
If you are evaluating vendors other than Fortinet, fill in the same list for every candidate; our comparison of FortiGate with Palo Alto, Sophos and Check Point shows which headings genuinely differ between vendors. As an independent solution partner, our approach is to complete this list first and pick the model last; projects that do it the other way round either pay for unused capacity or turn the appliance into a bottleneck at the first line upgrade.
Frequently Asked Questions
What is the most important criterion when an SMB chooses a firewall?
The Threat Protection throughput measured with all security profiles enabled, and who will manage the appliance. The raw Firewall throughput figure on the datasheet does not reflect real operating conditions; capacity drops noticeably once inspection is enabled. An unmanaged appliance, however powerful, provides no protection.
What is the difference between Firewall throughput and Threat Protection throughput?
Firewall throughput is the raw forwarding speed measured with no security profile enabled. Threat Protection throughput is measured with IPS, antivirus and application control enabled at the same time. On the FortiGate 60F, for example, the first is 10 Gbps and the second 700 Mbps; the decision is based on the second.
Which FortiGate model suits how many users?
Fortinet datasheets do not publish user counts; the traffic profile is what matters. As a general frame, the 40F is considered for micro offices and POS sites, the 60F for a classic branch, the 70G for offices running SSL inspection and the 90G as the hub of a multi-branch network. The final choice depends on line speed and the inspection decision.
Is enabling SSL/TLS inspection mandatory?
It is not mandatory, but without it the firewall cannot see malware inside encrypted traffic. The practical route is to exempt privacy-sensitive categories such as banking and healthcare and inspect the rest. This decision directly determines the SSL Inspection threshold of the model you select.
Does the firewall keep working when the license expires?
Yes; routing, policy and VPN functions continue to work. However, FortiGuard signature and database updates stop, IPS and antivirus remain on old signatures and web filtering categories are no longer refreshed. Writing the renewal date into the lifecycle plan prevents this gap.
Does KVKK make a firewall mandatory?
The Turkish Data Protection Authority's Personal Data Security Guide names the firewall and gateway as the first line of defense and lists them among the priority technical measures. There is no obligation to use a specific product, but there is an obligation to ensure data security. Verify the current legislation and the official guide.
Conclusion
Choosing the right firewall in 2026 is the sum of three decisions: a model whose Threat Protection and SSL Inspection capacity matches your needs profile, the license bundle that turns that model into a real NGFW, and the management model that keeps the appliance alive. An SMB that looks at the values measured with all protection enabled rather than the largest number on the datasheet, plans license and support tier together with the hardware, and places switches, Wi-Fi and remote access in the same architecture spends its budget on real protection rather than unused capacity.
To build your organization's profile together and compare candidate models and license bundles against your needs, you can schedule a free discovery call with the Sora Yazılım team and request a quotation based on a needs analysis.
